Hacker News new | ask | show | jobs
by ffamac 10 days ago
I purged OpenCode when I noticed it downloads npm packages in the background without asking the users first. This exposes higher risk of supply chain attach risk.